Description
The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information.
No analysis available yet.
Remediation
Vendor Solution
Update to version 3.5.8 or newer.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-21297 | The Ninja Forms WordPress plugin is vulnerable to sensitive information disclosure via the bulk_export_submissions function found in the ~/includes/Routes/Submissions.php file, in versions up to and including 3.5.7. This allows authenticated attackers to export all Ninja Forms submissions data via the /ninja-forms-submissions/export REST API which can include personally identifiable information. |
References
History
Mon, 31 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-31T18:12:36.488Z
Reserved: 2021-06-10T00:00:00.000Z
Link: CVE-2021-34647
Updated: 2024-08-04T00:19:47.750Z
Status : Modified
Published: 2021-09-22T18:15:11.217
Modified: 2024-11-21T06:10:53.220
Link: CVE-2021-34647
No data.
OpenCVE Enrichment
No data.
EUVD